Hackers actively exploit critical Roundcube flaw in code injection attacks
According to the Canadian Centre for Cyber Security, a high‑severity Roundcube webmail vulnerability patched in May is now being used in active code‑injection attacks.

The Canadian Centre for Cyber Security (CCCS) has warned that a critical Roundcube Webmail vulnerability, patched in May, is now being actively exploited in code‑injection attacks.
Roundcube is a widely deployed open‑source webmail client used by many organisations worldwide. The flaw stems from insufficient sanitisation of user input, allowing attackers to inject arbitrary code onto the server.
According to the CCCS advisory, the vulnerability is tracked as CVE-2024-??? (the exact identifier was not disclosed in the source) and was remedied by a May patch, but systems that have not applied the update remain exposed.
Attackers deliver malicious payloads via POST requests; once executed in the web interface, the code can be used to read email, alter filters, or even take full control of the affected server.
Security experts advise administrators to install the May patch immediately, monitor request logs for suspicious activity, and deploy a web application firewall or strict input validation to mitigate the risk.



